Courseiva

AZ-104 Manage Azure Identities and Governance Practice Question

Exhibit

Policy design notes:
- Scope: subscription
- Target: all resource groups
- Desired outcome: add tag CostCenter=042 automatically
- Requirement: do not block the deployment if the tag is omitted

Policy effects being considered:
- Deny
- Audit
- Append
- Modify

Based on the exhibit, a subscription policy must add CostCenter=042 to new resources, and deployments must not fail if the tag is missing. Which policy effect should you use?

⚠ Common exam trap

The trap is that candidates often choose 'Append' because it can add tags, but 'Modify' is the recommended effect for tag management. 'Modify' supports conflict resolution settings such as 'conflictEffect', which can be set to 'audit' to avoid deployment failures when the tag is missing. 'Append' is not deprecated, but it does not provide the same conflict-handling flexibility for tag updates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify

The 'Modify' effect (option D) is correct because it can add the CostCenter=042 tag to new resources without causing deployment failures if the tag is missing. Unlike 'Deny', which blocks non-compliant resources, 'Modify' uses a 'merge' operation to add tags during resource creation or update, and its 'conflictEffect' can be set to 'audit' to allow deployments to succeed. 'Append' is not deprecated and can also add tags, but 'Modify' is the recommended effect for tag management because it supports conflict resolution and can update existing tags.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deny

    Why it's wrong here

    Deny would block the deployment instead of allowing it to continue when the tag is missing.

    When this WOULD be correct

    Use Deny when you need to enforce that all new resources must have a specific tag, and you want to block creation of any resource that doesn't comply (e.g., to ensure cost tracking).

  • ✗

    Audit

    Why it's wrong here

    Audit only records non-compliance and does not automatically add the missing tag.

    When this WOULD be correct

    Use Audit when you need to evaluate compliance of existing resources or deployments without blocking them, such as when testing a new policy before enforcing it, or when you only need to report on non-compliance without automatic remediation.

  • ✗

    Append

    Why it's wrong here

    Append can add properties in some request scenarios, but it is not the best choice for automatic tag correction behavior.

    When this WOULD be correct

    Append would be correct if the policy needed to add a tag only to resources that lack it entirely, without modifying existing tags. For example, 'Add tag Environment=Production to all new resources that do not already have an Environment tag'.

  • ✓

    Modify

    Why this is correct

    Modify is used to automatically change resource requests, such as adding or correcting tags, without blocking deployment.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

✓ModifyCorrect answer▾

Why this is correct

Modify is used to automatically change resource requests, such as adding or correcting tags, without blocking deployment.

✗DenyWrong answer — click to see why▾

Why this is wrong here

Deny prevents creation of resources that don't have the tag, but the requirement states deployments must not fail if the tag is missing.

★ When this WOULD be the correct answer

Use Deny when you need to enforce that all new resources must have a specific tag, and you want to block creation of any resource that doesn't comply (e.g., to ensure cost tracking).

Why candidates choose this

Candidates may think Deny is the only way to enforce tagging, overlooking that Modify can add tags without blocking deployment.

✗AuditWrong answer — click to see why▾

Why this is wrong here

Audit only logs non-compliant resources without automatically adding the missing tag, so deployments would succeed but the tag would not be added, failing to meet the requirement to add CostCenter=042 to new resources.

★ When this WOULD be the correct answer

Use Audit when you need to evaluate compliance of existing resources or deployments without blocking them, such as when testing a new policy before enforcing it, or when you only need to report on non-compliance without automatic remediation.

Why candidates choose this

Candidates may think Audit is sufficient because it logs missing tags, but they overlook the requirement to automatically add the tag, assuming logging alone satisfies the policy goal.

✗AppendWrong answer — click to see why▾

Why this is wrong here

Append only adds the tag if it's missing but does not correct existing tags with different values; Modify can add or change the tag value. The question requires adding CostCenter=042, and Append would fail to update resources that already have a different CostCenter value.

★ When this WOULD be the correct answer

Append would be correct if the policy needed to add a tag only to resources that lack it entirely, without modifying existing tags. For example, 'Add tag Environment=Production to all new resources that do not already have an Environment tag'.

Why candidates choose this

Candidates may confuse Append with Modify, thinking Append can also change existing values, or they may overlook the requirement to handle resources with an existing different tag value.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,053 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.